← Vulnerability feed

Vulnerability record · CVE-2008-1867 · published 17 April 2008

CVE-2008-1867: Pixel motion blog sql injection vulnerability

Pixel Motion · Pixel Motion Blog

SQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL commands via the categorie parameter to index.php, possibly related to include/requetesIndex.php.

7.5 CVSS 2.0 High EPSS 0.97% · top 39.7% CWE-89 · SQL injection
7.5CVSS 2.0 base score
0.97%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL commands via the categorie parameter to index.php, possibly related to include/requetesIndex.php.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-1867 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2008-1866Pixel motion blog code injection vulnerabilityadmin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to uploa…EPSS 5.2%7.5CVE-2008-1868Pixel motion blog improper authentication vulnerabilityadmin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database b…EPSS 2.6%7.5CVE-2006-5085Blog Pixel Motion config.php static code injection enables PHP executionBlog Pixel Motion 2.1.1 writes the nom_blog parameter from config.php into include/variables.php without sanitization, allowing injected PHP code to …EPSS 47%analysed7.5CVE-2006-1426Pixel motion blog vulnerabilityMultiple SQL injection vulnerabilities in Pixel Motion Blog allow remote attackers to execute arbitrary SQL commands via the (1) date parameter in in…EPSS 2.0%6.4CVE-2006-5086Pixel motion blog vulnerabilityBlog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with m…EPSS 1.2%4.3CVE-2008-1986Pixel motion blog cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in liste_article.php in Blog Pixel Motion (aka PixelMotion) allows remote attackers to inject arbitrary web …EPSS 1.4%9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed9.3CVE-2026-9586Sangoma Switchvox unauthenticated SQL injection in /pa endpointSangoma Switchvox SMB Edition 8.3 (104997) fails to sanitize the PhoneIP value from XML content beginning with <PolycomIPPhone> before concatenating …KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2008-1867), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.